Threat reportVulnerabilityTL-2026-0241
Wing FTP Server RCE Exploit Chain — Lua Code Injection via NULL Byte (CVE-2025-47812 CVSS 10.0 + CVE-2025-47813)
Wing FTP Server RCE Exploit Chain (TL-2026-0241), also tracked as Wing FTP NULL Byte RCE, is a critical-severity software vulnerability scored CVSS 10, first published 2026-03-17. It has no confirmed attribution, affects wftpserver Wing FTP Server, references 2 CVEs (CVE-2025-47812, CVE-2025-47813), maps to 15 MITRE ATT&CK techniques (T1027, T1059, T1068), and is covered by 9 detection rules and 16 indicators of compromise.
- CVSS
- 10/10Critical
- CVEs
- 2Referenced vulnerabilities
- Techniques
- 15MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 16Indicators of compromise
Key facts for TL-2026-0241
- Threat ID
- TL-2026-0241
- Also known as
- Wing FTP NULL Byte RCE, Wing FTP Lua Injection
- Severity
- CRITICAL
- CVSS
- 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
- Status
- MONITORING
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- government, financial, healthcare, technology, manufacturing, education, critical-infrastructure, small-business
- Target regions
- North America, Europe, Asia-Pacific, Global
- Detection rules
- 9
- Indicators of compromise
- 16
Malware and tooling in Wing FTP Server RCE Exploit Chain
Malware and tooling: CVE-2025-47812 Python PoC exploit (4m3rr0r / EDB-52347), ScreenConnect
How Wing FTP Server RCE Exploit Chain works
Critical exploit chain in Wing FTP Server before 7.4.4 achieves unauthenticated remote code execution as SYSTEM/root. CVE-2025-47813 (CVSS 4.3) discloses the full server installation path via crafted UID cookies, while CVE-2025-47812 (CVSS 10.0) exploits NULL byte mishandling in the username parameter to inject arbitrary Lua code into session files, which execute with service-level privileges. Public PoC available since June 2025; active exploitation confirmed by Huntress since July 1, 2025. CISA KEV additions: CVE-2025-47812 on July 14, 2025; CVE-2025-47813 on March 16, 2026.
Wing FTP Server versions prior to 7.4.4 contain a critical exploit chain combining two vulnerabilities that together achieve unauthenticated remote code execution with SYSTEM (Windows) or root (Linux/macOS) privileges.
## CVE-2025-47812 — Lua Code Injection via NULL Byte (CVSS 10.0)
The core RCE vulnerability stems from improper handling of NULL bytes (\0) in both the user and admin web interfaces. The exploit chain operates through four interconnected weaknesses:
1. **NULL Byte Truncation in Authentication**: The c_CheckUser() function uses strlen() on the provided username. When a NULL byte (%00) is injected into the username, strlen() truncates the string at that point, causing authentication to succeed for the portion before the NULL byte. This allows exploitation via anonymous FTP accounts or any known credentials.
2. **Unsanitized Session Creation**: Despite authentication validating only the truncated portion, the rawset(_SESSION, 'username', username) call in loginok.html preserves the entire unsanitized username from request parameters, including the NULL byte and all subsequent characters.
3. **Lua Script Session Storage**: Wing FTP Server stores session data as executable Lua scripts on disk. The injected payload — crafted as valid Lua code after the NULL byte — is written directly into the session file.
4. **Session File Execution**: When an authenticated endpoint (specifically /dir.html) is accessed with the session UID cookie, the SessionModule.load() function executes session files via loadfile(filepath) followed by f(), triggering the injected Lua payload with full service-level privileges.
A typical exploit payload follows this structure: `anonymous%00]]%0dlocal+h+%3d+io.popen("command")%0dlocal+r+%3d+h%3aread("*a")%0dh%3aclose()%0dprint(r)%0d--` where `]]` closes the existing Lua table syntax, `io.popen()` executes arbitrary system commands, and `--` comments out remaining session data.
The attack requires only two HTTP requests: (1) a POST to /loginok.html with the crafted payload in the username parameter, and (2) a GET to /dir.html with the returned UID cookie to trigger execution.
## CVE-2025-47813 — Installation Path Disclosure (CVSS 4.3)
The loginok.html endpoint in Wing FTP Server before 7.4.4 discloses the full local installation path when an excessively long string is submitted in the UID cookie. This information disclosure (CWE-209) reveals sensitive server configuration details that aid exploitation of CVE-2025-47812 by exposing the exact filesystem location of session files.
## Active Exploitation
Huntress observed the first in-the-wild exploitation on July 1, 2025 — one day after Julien Ahrens (RCE Security) published the detailed vulnerability write-up and PoC on June 30, 2025. The patch (v7.4.4) had been available since May 14, 2025, but many installations remained unpatched.
Multiple distinct threat actors were observed exploiting the same victim from different IP addresses. Post-exploitation activity included network reconnaissance, creation of new local user accounts for persistence, attempted download and execution of malicious batch files, and deployment of ScreenConnect (ConnectWise Control) remote monitoring and management software. Microsoft Defender blocked several malicious activities on the compromised host.
Censys identified approximately 8,103 exposed Wing FTP Server instances as of July 9, 2025, with roughly 5,004 having exposed web interfaces potentially vulnerable to exploitation. Only 105 devices publicly reported version numbers.
## Related Vulnerabilities
CVE-2025-47811 is an additional privilege escalation vulnerability in Wing FTP Server that remains UNFIXED even in v7.4.4. CVE-2025-27889, an information disclosure flaw revealing cleartext passwords, was fixed in v7.4.3 (released March 26, 2025).
## Impact
Successful exploitation grants full SYSTEM/root-level command execution on the underlying server, enabling complete compromise of the host including data exfiltration, lateral movement, ransomware deployment, and persistent backdoor installation. The vulnerability is particularly dangerous because Wing FTP Server typically runs with maximum privileges by default and is commonly deployed as an internet-facing file transfer solution.
MITRE ATT&CK techniques used in TL-2026-0241
defense-evasion
T1027 Obfuscated Files or Information; T1070 Indicator Removal; T1078 Valid Accounts
execution
T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution
privilege-escalation
T1068 Exploitation for Privilege Escalation
command-and-control
T1071 Application Layer Protocol; T1219 Remote Access Tools
discovery
T1082 System Information Discovery; T1083 File and Directory Discovery; T1087 Account Discovery
persistence
T1136 Create Account; T1505 Server Software Component
initial-access
T1190 Exploit Public-Facing Application
impact
Affected products and versions in Wing FTP Server RCE Exploit Chain
- wftpserver — Wing FTP Server
Vulnerable versions: 7.4.3 and earlier; All versions before 7.4.4
Fixed in: 7.4.4
Remediation for Wing FTP Server RCE Exploit Chain
Patches
- Wing FTP Server v7.4.4 — fixes CVE-2025-47812 and CVE-2025-47813 (released May 14, 2025)
- Wing FTP Server v7.4.3 — fixes CVE-2025-27889 cleartext password disclosure (released March 26, 2025)
- Note: CVE-2025-47811 privilege escalation remains UNFIXED in v7.4.4
Immediate actions
- Update Wing FTP Server to version 7.4.4 or later immediately
- If patching is not immediately possible, disable anonymous FTP access
- Restrict access to Wing FTP web admin and user interfaces (/loginok.html, /dir.html) to trusted IP ranges only
- Monitor Wing FTP Server logs for POST requests to /loginok.html containing NULL byte sequences (%00) in the username parameter
- Audit local user accounts on Wing FTP Server hosts for unauthorized additions
- Block known ScreenConnect/ConnectWise Control domains at the firewall if not authorized
Workarounds
- Disable anonymous FTP access on all Wing FTP Server instances
- Place Wing FTP web interfaces behind VPN or restrict to internal networks only
- Implement IP allowlisting for web admin and user interface access
- Enable verbose logging and monitor for suspicious POST payloads to /loginok.html
- Deploy host-based intrusion prevention (HIPS) to block Lua script injection into session files
Longer-term hardening
- Deploy EDR/XDR with behavioral detection for anomalous child process spawning from wingftp.exe or wftpd processes
- Implement network segmentation to isolate file transfer servers from critical infrastructure
- Establish a vulnerability management program with SLA-based patching for internet-facing services
- Deploy WAF rules to detect and block NULL byte injection attempts in POST parameters
- Consider migrating to a file transfer solution with a stronger security track record
- Implement application allowlisting on Wing FTP Server hosts to prevent unauthorized binary execution
CVEs associated with Wing FTP Server RCE Exploit Chain
Weaknesses (CWE) in Wing FTP Server RCE Exploit Chain
Timeline of Wing FTP Server RCE Exploit Chain
- Wing FTP Server v7.4.3 released, fixing CVE-2025-27889 (cleartext password disclosure) but not CVE-2025-47812 or CVE-2025-47813
- Wing FTP Server v7.4.4 released, fixing CVE-2025-47812 (Lua injection RCE) and CVE-2025-47813 (path disclosure). CVE-2025-47811 privilege escalation remains unfixed
- Julien Ahrens (RCE Security / @MrTuxracer) publishes detailed vulnerability write-up and proof-of-concept exploits for CVE-2025-47812, CVE-2025-47813, and CVE-2025-47811
- Huntress observes first in-the-wild exploitation of CVE-2025-47812 on a customer environment — one day after PoC publication. Multiple threat actors observed performing recon, creating accounts, deploying ScreenConnect
- Huntress publishes detailed exploitation analysis documenting post-exploitation activities including reconnaissance, local account creation, batch file download attempts, and ScreenConnect deployment
- Censys identifies approximately 8,103 exposed Wing FTP Server instances globally, with 5,004 having exposed web interfaces vulnerable to the exploit chain
- NVD publishes CVE-2025-47812 (CVSS 10.0) and CVE-2025-47813 (CVSS 4.3). Public PoC exploit (EDB-52347) listed on Exploit-DB
- CISA adds CVE-2025-47812 to the Known Exploited Vulnerabilities (KEV) catalog with remediation due date of August 4, 2025 under BOD 22-01
- CISA adds CVE-2025-47813 to the KEV catalog, recognizing the full exploit chain. Remediation due date March 30, 2026. Renewed exploitation activity against unpatched Wing FTP instances confirmed
- As of 2026-05-29, this Wing FTP RCE chain is patched in v7.4.4 but remains an active threat to unpatched, internet-exposed servers (8,000+ originally exposed, anonymous-FTP exploitable). CVE-2025-47812 has been in CISA KEV since Jul 2025 and CVE-2025-47813 was added Mar 16 2026 with continued exploitation reported, so it stays under MONITORING.
Sources cited for Wing FTP Server RCE Exploit Chain
- NVD — CVE-2025-47812
- NVD — CVE-2025-47813
- CISA Known Exploited Vulnerabilities Catalog
- Huntress — Wing FTP Server RCE (CVE-2025-47812) Exploited in the Wild
- Exploit-DB — Wing FTP Server 7.4.3 Unauthenticated RCE (EDB-52347)
- GitHub PoC — CVE-2025-47812 Exploit
- Censys Advisory — Unauthenticated RCE in Wing FTP Server
- ZeroPath — Wing FTP Server NULL Byte RCE Analysis
- Help Net Security — Critical Wing FTP Vulnerability Exploited in the Wild
- The Hacker News — CISA Flags Actively Exploited Wing FTP Vulnerability
- Fidelis Security — CVE-2025-47812 Wing FTP RCE Vulnerability
- Cynet — Wing FTP Post Authentication RCE CVE-2025-47812
- SecurityWeek — CISA Flags Year-Old Wing FTP Vulnerability as Exploited
- Wing FTP Server Security Advisory
Detection coverage for TL-2026-0241
As of 2026-03-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0241 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.